DVA-C02 Security Practice Question
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"logs:CreateLogGroup"
],
"Resource": "*"
}
]
}A developer is troubleshooting an AccessDenied error when a Lambda function tries to write to CloudWatch Logs. The function's IAM role includes the following policy. Which TWO missing permissions are causing the error? (Choose TWO.)
⚠ Common exam trap
Many candidates assume only PutLogEvents is needed for writing logs, forgetting that the Lambda runtime must also create the log stream if it does not already exist, making CreateLogStream a required permission.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
logs:CreateLogStream
A Lambda function must call logs:CreateLogStream before it can write log events to a specific log stream. Without this permission, the function cannot create a new log stream when one does not already exist, resulting in an AccessDenied error. Option E is correct because logs:PutLogEvents is the permission required to actually write log events to an existing log stream; without it, the function cannot send log data to CloudWatch Logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
logs:DescribeLogStreams
Why it's wrong here
The logs:DescribeLogStreams permission allows an entity to list and retrieve metadata about log streams within a specified log group, such as their creation time or ARN. While useful for discovery, monitoring, or management purposes, it is not directly required for the act of writing log events. An AccessDenied error during a log write operation indicates a failure to perform the write action itself, not a failure to enumerate existing streams.
- ✗
logs:CreateLogGroup
Why it's wrong here
The logs:CreateLogGroup permission is required to initially establish a new log group within CloudWatch Logs. However, if the log group already exists and the application is attempting to write to it, this specific permission is not needed for subsequent log writing operations. An AccessDenied error during log event ingestion typically indicates a missing permission related to creating streams or putting events within an established group, not the group's initial creation.
- ✓
logs:CreateLogStream
Why this is correct
The logs:CreateLogStream permission is absolutely essential for an application to establish a new log stream within an existing CloudWatch Log Group. If the application attempts to write log events to a stream that does not yet exist, and it lacks this specific permission, it will inevitably encounter an AccessDenied error. This permission enables the necessary infrastructure for subsequent PutLogEvents calls to succeed.
- ✗
logs:GetLogEvents
Why it's wrong here
The logs:GetLogEvents permission is exclusively used for retrieving log events from a specific log stream, allowing users or applications to read historical data. It is a purely read-only operation and has no bearing on an application's ability to publish new log data. Therefore, an AccessDenied error encountered when an application is attempting to write new log events would not be resolved by adding this permission.
- ✓
logs:PutLogEvents
Why this is correct
The logs:PutLogEvents permission is fundamental for an application to publish actual log data into a CloudWatch Log Stream. Once a log group and log stream have been successfully created, this permission allows the application to send individual log events, including their timestamp and message, to be stored within that stream. Without logs:PutLogEvents, the application cannot successfully transmit any log data, leading to an AccessDenied error.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.